PT-2024-33484 · Sandboxie · Sandboxie

·

CVE-2024-49360

·

Published

2024-11-29

·

Updated

2025-08-04

CVSS v3.1

9.2

Critical

VectorAV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Sandboxie (affected versions not specified)
Description Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. An authenticated user (UserA) without privileges can read files created in a sandbox belonging to other users within the C:SandboxUserBxxx folders. An attacker using explorer.exe or cmd.exe outside of a sandbox can also read other users' files in C:Sandboxxxx. The issue involves Sandboxie failing to reset Access Control Lists (ACLs) when a user creates a folder (C:SandboxUserA) with malicious ACLs, potentially allowing unauthorized access to files. All files edited or created during sandbox processing are affected.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-49360
GHSA-4CHJ-3C28-GVMP

Affected Products

Sandboxie